Windows Recall, the controversial Windows 11 “photographic memory” feature launched almost 2 years ago, is yet again making security researchers nervous. One in particular—the same cybersecurity professional who hacked Recall shortly after it was announced—says Microsoft’s updated safeguards still leave users exposed if attackers gain local access to a PC. While Recall’s data is reportedly protected by a strong encryption system, that protection wanes once decrypted screenshots and text leave the secure environment and go through everyday Windows processes.
Recall runs on Copilot+ PCs and works by taking periodic screenshots of activity on the screen, then making them searchable locally. Experts say it can capture banking details, medical information, chats (even those you think are private), internal corporate documents, and more, creating a trove of sensitive data.
Alexander Hagenah, whose earlier proof‑of‑concept tool exposed flaws in the initial version of Recall, has released a tool called TotalRecall Reloaded that intercepts Recall’s content after a user unlocks it with Windows Hello. The tool runs under the victim’s account and quietly collects their Recall history. Without them knowing, what many people see as a valuable feature becomes a valuable source of information for malware.
Hagenah shared on LinkedIn that he reported Recall’s latest vulnerabilities to Microsoft in March.
“Microsoft closed the case as ‘Not a Vulnerability,’ stating that ‘the access patterns demonstrated are consistent with intended protections and existing controls, and they do not represent a bypass of a security boundary or unauthorized access to data,'” Hagenah wrote. “Microsoft says this is by design. That worries me.”
Microsoft says Recall is turned off by default and stores data only on the device, uses strong encryption and a secure enclave, and requires biometric or PIN authentication with presence detection to open. But none of this works once an attacker runs malicious code as a logged‑in user.

